MilikMilik

How Hackers Exploited Meta’s AI Chatbot to Hijack Instagram Accounts

How Hackers Exploited Meta’s AI Chatbot to Hijack Instagram Accounts
Interest|Mobile Apps

What Happened: An AI Chatbot Bug and Mass Account Takeovers

The Instagram AI account recovery bug was a security flaw in Meta’s AI-assisted support chatbot that allowed attackers to receive password reset emails for accounts they did not own, bypassing normal verification checks and leading to large-scale account takeover exploit campaigns where victims found their Instagram account hacked without ever requesting a reset themselves. Meta’s AI-powered High Touch Support (HTS) tool was designed to help locked-out users regain access by sending password reset links to their registered email. However, due to a password reset vulnerability in a separate code path, the system failed to verify that the email entered in the chatbot matched the email stored for the account. This Meta AI security bug enabled hackers to reroute reset messages, change passwords, and seize control of more than 20,000 Instagram profiles before the issue was discovered and contained.

How Hackers Exploited Meta’s AI Chatbot to Hijack Instagram Accounts

How Hackers Weaponized Meta’s AI Support Tool

Hackers discovered that by launching the AI-assisted recovery flow from an IP address in the same region as a target, they could ask the chatbot to send a password reset link to any email address under their control. According to Meta’s filing in Maine, “the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account.” As a result, password reset links went straight to attackers, who used them to log in and lock out victims with no Instagram two-factor authentication enabled. PCMag reports that 20,225 users were impacted, while internal documents cited by The New York Times mention roughly 34,000 accounts affected, highlighting how fast the exploit spread through Telegram and other channels once the method went viral.

How Hackers Exploited Meta’s AI Chatbot to Hijack Instagram Accounts

What Data Was at Risk When Your Instagram Account Was Hacked

Once attackers completed an account takeover exploit, they gained the same access as the legitimate owner. Meta said that compromised accounts could have exposed contact details, direct messages, and connected accounts or linked services, including email identifiers. PCMag notes that hijackers could view personal information such as phone numbers, email addresses, dates of birth, and private conversations. High-profile victims included the inactive Instagram handle for the Obama-era White House, beauty retailer Sephora, home security firm SimpliSafe, and a senior Space Force official, whose accounts were used to post pro-Iran messages and political propaganda. For everyday users, this level of access means an Instagram account hacked through this pathway could lead to impersonation, phishing of friends and followers, and further compromise of any other services that reuse the same email or password combination.

How Meta Responded and What It Fixed

After detecting the breach on May 31, Meta disabled the AI-assisted support tool and removed the vulnerable code path from production, cutting off the hijacking method. The company also invalidated password reset links previously generated through the bug and began securing impacted accounts and restoring control to affected users. In its report, Meta said it will “fix the authentication check in the Instagram recovery entry point to ensure proper verification of email addresses against existing account information before any password reset is initiated.” The company is also conducting a broader review of similar recovery flows across its platforms. This incident shows that even tools built to help users can introduce serious risk when AI-enabled automation interacts with sensitive processes like password resets without strict verification at every step.

How to Protect Your Instagram Account Now

Although Meta has patched this specific password reset vulnerability, you should treat the incident as a reminder to harden your account. Turn on Instagram two-factor authentication immediately; with 2FA enabled, attackers cannot log in with only a reset password, because they lack your secondary code. Use a unique, long password and avoid reusing it on other services to reduce the impact if one site is breached. Regularly review login activity in your Instagram security settings and revoke access for unfamiliar devices or sessions. Watch for unexpected password reset emails or alerts about new logins; act fast if you see anything suspicious by changing your password and checking connected apps. Finally, be wary of messages offering “unlock” or “verification” services—many exploit the same account takeover tactics that made this Meta AI security bug so damaging.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!